NESA, DESC, CBUAE, TDRA, PDPL — the UAE has several cybersecurity regimes, and they overlap enough to be genuinely confusing. Which one applies to you depends on your sector and who you serve, and it decides what testing you need and how often. This guide untangles them so you know exactly where you stand.

The short answer

Your regulator follows your sector. Federal entities and critical infrastructure answer to NESA (UAE Information Assurance Standards). Dubai government bodies and their suppliers answer to DESC. Banks, finance companies and payment providers answer to the CBUAE. Telecom and digital service providers fall under TDRA, and anyone processing personal data is covered by the UAE PDPL. In practice, nearly all of them expect vulnerability assessment and penetration testing (VAPT) at least annually.

The regimes at a glance

Regime Who it applies to Testing it expects Frequency
NESA / UAE IA Federal entities & critical-infrastructure operators Vulnerability assessment & penetration testing in a managed programme At least annually + after major changes
DESC (ISR) Dubai government entities & their suppliers Regular, independent testing with remediation evidence Regular; risk-based
CBUAE Banks, finance companies, exchange houses, payment providers Vulnerability management & penetration testing; red teaming for mature programmes Risk-based, often > annually
TDRA Telecom & digital service providers Security assurance for the services they run Ongoing assurance
UAE PDPL Any organisation processing personal data Appropriate technical measures — testing to prove they work Demonstrable & effective

Which applies to you?

Start from your sector and who you serve.

  • Government & critical infrastructureFederal → NESA. Dubai government or a supplier to one → DESC. Often both signals apply if you serve Dubai government from a critical sector.
  • Financial servicesBanks, finance companies, exchanges and payment providers → CBUAE, which expects a risk-based testing programme, frequently including red teaming.
  • Telecom & digital servicesProviders of telecom and digital government services → TDRA security-assurance expectations.
  • Everyone handling personal dataThe UAE PDPL applies across sectors: you must protect personal data and be able to show the measures are effective — independent testing is how.

Frequently asked questions

What is the difference between NESA and DESC?

NESA sets the federal UAE Information Assurance Standards for government entities and critical-infrastructure operators nationwide. DESC is Dubai’s own regulator, whose Information Security Regulation applies to Dubai government entities and their suppliers. If you serve Dubai government from a critical sector, both can be relevant.

Does NESA require penetration testing?

Yes. The UAE IA Standards NESA oversees expect regular vulnerability assessments and penetration testing as part of a managed security programme, typically at least annually and after significant changes.

Does CBUAE require VAPT or red teaming?

CBUAE frameworks expect financial institutions to run a risk-based testing programme covering vulnerability management and penetration testing. More mature institutions are often expected to add red teaming or threat-led testing.

Can one test satisfy more than one regulator?

Often yes. A well-scoped VAPT with audit-ready reporting can produce evidence relevant to several regimes at once, provided the report maps findings to each framework you need. That mapping is where scoping matters.

How often do we need to test?

At least annually plus after any major change is the common baseline for NESA and DESC. CBUAE-regulated firms often test more frequently on a risk basis. Our cost guide explains how frequency and scope affect the engagement.